CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
20 May, 2008
17:09:32
408 - PIRT Operation Timed Out
ID826825 (termination link)
TitleBotnet, PayPal
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp14 May, 2008 @ 17:21:46
Topic ID221718 - Read/respond to PIRT commentary.
Handler Note:
14 May, 2008
17:34:12
downie: Consumed following related reports:

[824910] http://paypal.client-records.com/
[825005] http://PayPal.Client-Records.com/
[825070] http://paypal.client-records.com/.
Handler Note:
14 May, 2008
17:51:34
downie: The URL accesses a PayPal phishing site hosted on a bot net.
IP addresses 68.63.146.167, 71.138.23.154, 76.122.177.31, 76.244.109.194, 77.103.156.54, 79.78.251.60, 82.1.101.170, 82.1.138.130, 82.37.81.101, 98.209.206.129 were active at Wed, 14 May 2008 17:12:56 +0000 (GMT).
Nameservers
NS3.B546EC5A89.COM [68.45.176.12] response 68.63.146.167, 71.138.23.154, 76.122.177.31, 76.244.109.194, 77.103.156.54, 79.78.251.60, 82.1.101.170, 82.1.138.130, 82.37.81.101, 98.209.206.129 in 185 mSec
were active at the same time
=================================
REGISTRAR PAYCENTER:
Domain CLIENT-RECORDS.COM has been registered with PAYCENTER for fraudulent purposes.
It is being used for a fake PayPal site hosted on a bot net.
Please suspend this domain immediately to prevent further criminal activity.
Please also check for any domains registered using the same (stolen) identity and credit card details, or the same email address.
=================================
REGISTRAR DNS.COM.CN:
Domain B546EC5A89.COM has been registered with DNS.COM.CN for fraudulent purposes.
It is operating nameservers for phishing sites hosted on a bot net.
Please suspend this domain immediately and remove the nameserver glue records (see http://spamtrackers.eu/wiki/index.php?title=Registrar_Advice) to prevent further criminal activity.
Please also check for any domains registered using the same (stolen) identity and credit card details, or the same email address.
=================================
NAMESERVER HOST COMCAST:
Nameservers
NS3.B546EC5A89.COM [68.45.176.12] - response 185 mSec
NS6.B546EC5A89.COM [68.45.176.12]
have been set up on your network to serve addresses for this phishing domain and others.
No legitimate domains use these nameservers.
Please shut them down urgently.
Please close the customer's account.
If possible please also be alert for anyone setting up other nameservers on your network for this domain.
=================================
HOSTS: TELEWEST,NTL,TISCALI,AT&T,COMCAST
IP addresses 68.63.146.167, 71.138.23.154, 76.122.177.31, 76.244.109.194, 77.103.156.54, 79.78.251.60, 82.1.101.170, 82.1.138.130, 82.37.81.101, 98.209.206.129 were running infected computers as part of a botnet at the above time, serving phishing pages.
=================================
Handler Note:
14 May, 2008
17:58:32
downie: View CIDR AS33287 Report: http://www.cidr-report.org/cgi-bin/as-report?as=33287

"33287 | US | arin | 2004-11-16 | DNEO-OSP4 - Comcast Cable Communications, Inc."

Handler Note:
14 May, 2008
17:58:32
downie: Extended information for AS33287:
State/Province: nj
Country: us
Responsible Domain: comcast.net
Abuse Email: abuse@comcast.net
Handler Note:
14 May, 2008
18:16:05
downie: Generated and sent email phish alert to respective parties.
Handler Note:
20 May, 2008
21:12:21
downie: DNS lookup refused
Auto DupePaul: Auto Consumed following related reports:

14 May, 2008 @ 18:38:13
[827151] http://paypal.client-records.com/index.htm
14 May, 2008 @ 19:46:25
[827355] http://PayPal.Client-Records.com/=20
15 May, 2008 @ 01:08:44
[828141] http://paypal.client-records.com/details.php
15 May, 2008 @ 01:09:34
[828143] http://www.client-records.com/
15 May, 2008 @ 01:09:59
[828146] http://www.client-records.com/index.htm
15 May, 2008 @ 01:29:24
[828198] http://PayPal.Client-Records.com
15 May, 2008 @ 05:51:05
[828385] http://paypal.client-records.com/login.php
Fetched URLs
Slaves824910, 825005, 825070, 827151, 827355, 828141, 828143, 828146, 828198, 828385,

Report for at 14 May, 2008 @ 17:06:06


fetched page

at 14 May, 2008 @ 18:04:28
MD5 Fingerprint: b30cca8b73f7a5aed21e8bf80e3a281e
SHA1 Fingerprint: 45723395e43c54114b6b83a924e7201e2cbe80e2

fetched page

at 14 May, 2008 @ 18:05:35
MD5 Fingerprint: fa792e510a468f1bc0b00991066e44da
SHA1 Fingerprint: d88a9ea13c0edbf139a61b733236cff1d71d2efa

fetched page

at 14 May, 2008 @ 18:06:24
MD5 Fingerprint: 7c8c4091d318ff223f1bfd77b2d53ded
SHA1 Fingerprint: e3a4d159f46f6c4407d034dfaafc29c927d69e99

fetched page

at 14 May, 2008 @ 18:07:13
MD5 Fingerprint: a0c00c06e0d630bf422668fec0811b1e
SHA1 Fingerprint: 871a89d3104c8a64bd32f9ccb18dda9da69c5374

fetched page

at 14 May, 2008 @ 18:10:29
MD5 Fingerprint: de66dd246f0be87c20c641bf89bee662
SHA1 Fingerprint: ba3cad9e15a58cc377ce26134648651267383d87